Skip to content

The Agent Portfolio: Why Enterprises Need Fewer Agents with Clearer Owners

Published: at 08:20 AMSuggest Changes

A CIO asked her platform team a simple question in a quarterly review: how many AI agents are running in the business today? The answer took three weeks, arrived as four spreadsheets that disagreed with each other, and included two agents that had been switched off months earlier. Three more had no named owner. One had permission to write to the customer record system and nobody could explain why.

The uncomfortable part was not the mess. It was that the organisation had spent the previous quarter debating agent governance, autonomy levels and guardrails while being unable to answer the most basic question in the room.

That is the shift worth naming. The interesting question about enterprise agents is no longer whether a single one works. It is whether the population of them is worth what it costs to run, monitor and defend. That is portfolio management, and most organisations have not started it.

Discovery is not control

Gartner’s May 2026 research makes the cost of that gap concrete. It predicts that by 2027, 40% of enterprises will demote or decommission autonomous AI agents because governance gaps were found only after something went wrong in production. The same release argues the root cause is treating governance as binary: either locked down or fully trusted. Shiva Varma, a senior director analyst at Gartner, notes that applying identical controls to agents at different autonomy levels produces two failure modes. Simple agents get over-restricted, which slows delivery and pushes teams into shadow development. More autonomous agents get under-restricted, which widens operational, security and compliance risk. [Gartner, May 2026]

Read that as a warning about portfolio design rather than model quality. The organisations at risk are the ones holding an agent population nobody can enumerate, tier or retire, however capable their models happen to be.

The Cloud Security Alliance’s April 2026 survey, commissioned by Token Security, shows how confidently that blindness is held. 68% of respondents reported high confidence in their visibility into agents. Within the same group, 82% had discovered shadow AI agents in the previous year. 59% document what each agent is for, and 68% run permission reviews. Only 21% have a formal decommissioning process, and just 19% are confident they fully retire an agent once its purpose ends. [CSA, April 2026]

Put those numbers side by side and the pattern is clear: organisations feel confident about a population they have only partly found. Most believe they can see their agents because they can see the ones they sanctioned. The rest surface later, from internal automation environments, low-code platforms and productivity suites where business teams built something useful without telling anyone.

Consolidation is the cheapest control you can apply

I have sat in more than one review where three teams had each built a policy assistant. Same source documents, three sets of credentials, three owners, three different answers to the same staff question. None of them was wrong. Together they were indefensible, because no single person could explain what the organisation’s policy guidance actually said.

Overlap is the norm in a young agent estate, and it is also the easiest problem to fix. Rank agents by overlap and apply a merge test. Do they serve the same user group? Do they read the same data under the same boundary? Do they call the same tools? Does a failure cause the same consequence? When four answers line up, the organisation should have one agent with one owner, not four agents with four explanations.

Every retained agent carries fixed costs whether or not it is used: integration maintenance when upstream APIs change, credential rotation, evaluation upkeep, monitoring, incident surface and the tacit knowledge required to debug it at 2am. Duplication multiplies those fixed costs while adding nothing to the outcome. It also makes proportionate governance harder to apply, because a 200-agent estate cannot be tiered by hand.

Gartner’s argument for proportional controls assumes someone knows which agent sits at which autonomy level. That assumption only holds if the portfolio is small enough and documented well enough for the classification to mean something. Consolidation therefore matters well beyond tidiness: it is the precondition for every control the analyst recommends.

Every agent needs a sponsor and an exit

The minimum unit of portfolio management is a record with six fields.

Purpose, stated as the business outcome in one sentence a non-technical sponsor would sign their name to. Sponsor, the named business owner accountable for outcomes, exceptions and the retirement decision. Action authority, spelling out what the agent may do without a human approving and what must stop for review. Evidence trail, describing what is logged, how long it is retained and who can produce it on demand. Lifecycle cost, covering the full run cost rather than the licence line. Retirement trigger, the date or condition that forces a keep, merge, demote or retire decision.

This is not a novel standard. The April 2026 joint guidance from CISA, the NSA and the cyber agencies of Australia, Canada, New Zealand and the United Kingdom treats agent inventory, per-agent identity, tool allowlisting and decommissioning procedures as baseline expectations for any organisation adopting agentic services. It is the first coordinated Five Eyes guidance aimed at a single AI attack surface, which tells you how seriously the agencies regard the operating gap. [CISA and partners, April 2026]

Vendor platforms are converging on the same shape from the other direction. Microsoft’s Entra Agent ID documentation describes agent identity blueprints as templates that create parent-child relationships so consistent policy can be applied across large numbers of agents, alongside a unified registry, named sponsors and lifecycle management. Treat that as a vendor’s account of its own tooling, not independent evidence. The useful part is the acknowledgement that agent sprawl is now an identity and lifecycle problem, not a prompt problem. [Microsoft, 2026]

Keep this register distinct from a model inventory. A model register answers the question of what changes when a provider retires or upgrades something. An agent portfolio answers a different and harder question: who owns this, what may it do, and should it still exist at all. Organisations that conflate the two end up able to name every model in production while being unable to name the owner of the agent that uses it.

Fund the portfolio, not the count

Agent counting flatters a programme the way pilot counting once did. The number that matters is what each agent costs to keep alive and what it returns.

Build the lifecycle figure from its parts: inference and tool-call spend, retrieval and storage, monitoring and evaluation upkeep, human review and exception handling, integration maintenance, identity and credential management, and the rework created when it fails. Then compare it against completed, controlled tasks rather than conversations started. An agent that handles a high volume of trivial interactions cheaply can still be a poor investment once exception handling and review time are loaded onto its ledger.

That comparison changes portfolio decisions. An agent with a strong per-task cost and a clear owner earns expansion. An agent with a thin margin, a duplicate purpose and no sponsor earns retirement. An agent whose cost is fine but whose failure consequence has grown since launch earns demotion: narrower authority, more human approval, a smaller blast radius.

Four decisions, made quarterly

A portfolio review is only real if it produces one of four outcomes for each agent. Keep and harden. Merge with another agent. Demote the autonomy level. Retire it.

Assign the decision rights before the meeting. The sponsor proposes and owns the outcome. Security and risk set the floor that cannot be traded away, including identity, data boundary and audit expectations. The platform team supplies the evidence: usage, cost, incidents, evaluation results and identity status. Nobody needs a new central committee for this. A quarterly session with the right three or four people is enough, provided the record above exists to argue from.

Add one standing rule, because it prevents most of the mess: no new agent reaches production without a named sponsor, a written action-authority statement and a retirement trigger. That single gate converts an unbounded stream of enthusiastic experiments into a portfolio that someone can actually defend.

Then measure the portfolio itself, not just its members. Track the share of production agents with a current sponsor, the number of duplicates merged, agents retired on schedule, agents with a current evaluation, incidents traced to unregistered agents, and lifecycle cost per completed task. These are fitness functions for an operating discipline, and they expose drift long before a board question does.

Ask your platform and security leads for a list of every agent in production, the business owner of each, what it may do without a human approving, and the condition under which it will be retired. If that list takes more than a day to assemble, or if a meaningful share of it has no owner, you do not have an agent portfolio. You have a collection. Collections are not governed, funded or defended deliberately. They are inherited.

Sources


Previous Post
You Contracted for a Capability, Not a Change Process
Next Post
Every New Model Is a Production Change: Governing the AI Upgrade Cycle